This article was accepted into the corpus but its outbound wikilinks were never NER-processed — typical at the deepest BFS hop or when the run's entity cap was reached. No expansion funnel to show.
| Siku-2021 | |
|---|---|
| Name | Siku-2021 |
| Date | 2021 |
| Type | Cyber incident |
| Location | Global |
| Outcome | Major disruption |
Siku-2021 was a significant 2021 cyber incident that produced widespread disruption across multiple sectors and jurisdictions. It was reported contemporaneously alongside events involving Microsoft, Google, Amazon, Facebook, Twitter, and Apple Inc.. The incident attracted attention from agencies such as the United States Department of Homeland Security, National Security Agency, European Union Agency for Cybersecurity, INTERPOL, and affected entities including JPMorgan Chase, Citigroup, Deutsche Bank, BNP Paribas, HSBC.
Siku-2021 emerged amid heightened tensions involving actors linked to Russia, China, Iran, North Korea, and non-state groups akin to Anonymous (hacker group), Fancy Bear, Lazarus Group, and REvil. Prior incidents such as SolarWinds cyberattack, WannaCry ransomware attack, NotPetya, Equifax data breach, and Colonial Pipeline ransomware attack set precedent for cross-border disruption. Responses were informed by frameworks from NATO, G7, United Nations, Council of Europe, Organisation for Economic Co-operation and Development, World Bank, and International Monetary Fund. Key corporate actors referenced standards from ISO/IEC 27001, NIST Cybersecurity Framework, IETF, and CERT-EU.
The timeline began with reconnaissance activities similar to those in the 2016 Democratic National Committee cyber attacks and the 2017 WannaCry outbreak, followed by exploitation phases reminiscent of Stuxnet operation and Operation Aurora. Initial compromise vectors implicated supply chain channels used by SolarWinds, Kaseya, Microsoft Exchange, VMware, and Citrix Systems. Within days, incidents were reported by Royal Bank of Scotland, Barclays, ING Group, Standard Chartered, Tokyo Stock Exchange, Frankfurt Stock Exchange, NASDAQ, New York Stock Exchange, London Stock Exchange, Deutsche Börse, and Hong Kong Exchanges and Clearing. Governments including United Kingdom, France, Germany, Italy, Spain, Australia, Canada, Japan, South Korea, and India issued alerts coordinated with CERT-UK, ANSSI, BKA, AUSCERT, Canadian Centre for Cyber Security, and JPCERT/CC.
Technical analysis drew on methodologies from MITRE ATT&CK and tools used by CrowdStrike, Mandiant (FireEye), Kaspersky Lab, Symantec, Palo Alto Networks, Cisco Systems, Checkpoint Software Technologies, and McAfee. Attack vectors included zero-day exploitation comparable to CVE-2021-26855 patterns, privilege escalation like techniques seen in EternalBlue, lateral movement similar to Pass-the-Hash, and persistence methods akin to Golden SAML. Malware artifacts resembled families attributed to Cozy Bear, DarkSide, Conti, Ryuk, and TrickBot. Command-and-control infrastructure used hosting providers such as Akamai Technologies, Cloudflare, Fastly, OVHcloud, GoDaddy, and content-delivery networks employed by Cloudflare and Amazon Web Services. Data exfiltration patterns mirrored incidents reported by Marriott International, Target Corporation, Home Depot, Yahoo!, and Sony Pictures Entertainment.
Economic and operational impacts echoed losses described after NotPetya and Equifax breach, affecting Visa, Mastercard, PayPal, Stripe, SWIFT, and clearinghouses like The Depository Trust & Clearing Corporation. Critical infrastructure effects paralleled disruptions at Colonial Pipeline and Irish Health Service Executive, with healthcare providers such as Mayo Clinic, Kaiser Permanente, and NHS England reporting incidents. Media organizations including The New York Times, BBC, Reuters, Associated Press, CNN, and Al Jazeera covered cascading outages that affected Uber, Airbnb, Delta Air Lines, United Airlines, Marriott International, Hilton Worldwide, and public services in New York City, Los Angeles, London, Paris, Berlin, Rome, and Mumbai.
Attribution efforts involved cooperation among FBI, CISA, NSA, MI5, GCHQ, ANSSI, BKA, NCSC-NL, DFRLab, Europol, and private-sector firms including CrowdStrike, Mandiant, Kaspersky Lab, Recorded Future, Flashpoint, Lookout (company), and RiskIQ. Forensic techniques highlighted similarities to operations by Fancy Bear and Lazarus Group while also noting tradecraft overlap with Conti and REvil. Law enforcement actions referenced precedents from the 2018 sanctions on Russia, U.S. indictment of North Korean hackers, and EU cyber sanctions framework.
International responses invoked mechanisms like the Budapest Convention on Cybercrime, Tallinn Manual advisory concepts, UN Group of Governmental Experts, and sanctions regimes coordinated by European Union, United States Department of the Treasury, Office of Foreign Assets Control, United Kingdom HM Treasury, and G7. Legal actions mirrored lawsuits against Equifax and enforcement by regulators such as FTC, SEC, ICO (United Kingdom), CNIL (France), BaFin (Germany), ASIC (Australia), and Japan Financial Services Agency.
Siku-2021 prompted reforms reflecting recommendations from NIST, ISO, World Economic Forum, WEF Global Cybersecurity Outlook, OECD Guidelines on Cybersecurity, and institutional changes at DHS, NSA, GCHQ, ANSSI, and ENISA. Sectoral responses included enhanced resilience measures by SWIFT, FS-ISAC, ICANN, IETF, and cloud providers Microsoft Azure, Google Cloud Platform, Amazon Web Services. Academic analysis followed frameworks from RAND Corporation, Brookings Institution, Chatham House, Carnegie Endowment for International Peace, Harvard Kennedy School, Stanford Cyber Policy Center, and MITRE Corporation. The incident reinforced international dialogues at summits such as G20, NATO Summit, UN General Assembly, and Munich Security Conference.
Category:Cybersecurity incidents